Skip to main content
Owning a hardware wallet puts you in direct control of your crypto—but that control comes with responsibility. Trezor is designed to be highly secure, yet no device can protect you from every threat on its own. The habits you build around how you buy, use, and store your Trezor are just as important as the device itself. This guide covers the most impactful security practices every Trezor owner should follow.

Core Security Principles

Buy Only From Official Sources

Purchase your Trezor exclusively from trezor.io or an authorized reseller. A device bought secondhand or from an unofficial marketplace may have been tampered with before it reached you.

Verify Every Transaction on Device

Always read the recipient address and amount shown on your Trezor’s screen before pressing confirm. Never approve a transaction based solely on what your computer displays.

Keep Firmware Up to Date

Run the latest firmware to ensure you have all current security patches. Check for updates in Trezor Suite → Settings → Device and install them promptly.

Use a Strong PIN and Passphrase

Set a PIN of at least 6 digits to lock your device. For high-value holdings, enable a passphrase to create a hidden wallet that provides an additional layer of protection.

Protect Your Recovery Seed

Your 12- or 24-word recovery seed is the master key to your wallet. Anyone who obtains your seed can access your funds from any device, anywhere in the world—no PIN, no Trezor needed.
  • Write your seed on paper during setup. Never type it into any computer, phone, or website—not even Trezor Suite. Trezor Suite will never ask you to enter your seed.
  • Store it offline. Do not photograph your seed, store it in a password manager, or keep it in cloud storage. Physical, offline storage is the safest approach.
  • Keep multiple copies in separate secure locations. A single copy can be lost in a fire, flood, or theft. Two or three copies stored in geographically separate places (a home safe, a bank safe-deposit box, a trusted relative’s home) give you redundancy.
  • Consider a metal backup. Paper degrades over time and is vulnerable to fire and water. Metal seed storage plates are resistant to physical damage and provide long-term durability.
Never buy a Trezor that arrives with a pre-filled recovery seed card or a device that has already been “set up” by the seller. A legitimate Trezor ships blank. If someone else generated your seed, they already have a copy—and full access to any funds you deposit.

Verify Your Device Before Use

Before trusting a Trezor with real funds, confirm that it is genuine and untampered:
  • Check that the holographic seal on the packaging is intact and shows no signs of removal or reapplication.
  • When you first connect the device, Trezor Suite runs an authenticity check that cryptographically verifies the device is genuine Trezor hardware. Wait for this check to pass.
  • Inspect the physical device for signs of tampering—loose casing, unexpected components, or unusual connectors.

Avoid Common Attack Vectors

Always Use Official Software

Install Trezor Suite exclusively from suite.trezor.io. Fake Trezor applications are distributed through phishing emails, search-engine ads, and unofficial app stores. A counterfeit app can intercept your seed entry or display false addresses to redirect your funds.

Beware of Phishing

Attackers impersonate Trezor through emails, social-media messages, and websites that closely mimic trezor.io. They may claim your device needs immediate verification or that your funds are at risk. Trezor will never contact you by email asking for your seed, PIN, or passphrase. If you receive such a message, ignore it and report it.

Never Enter Your Seed Into Any Software

Legitimate recovery only happens on the Trezor device itself—word by word, entered directly on the hardware using the device’s buttons. If any website, app, or support agent asks you to type your seed phrase into a browser or software field, you are being targeted by a scam. Stop immediately.

Advanced Practices

For high-value or infrequent transactions, consider using a dedicated computer that is not used for everyday web browsing, email, or downloads. A clean machine with minimal software reduces the risk of malware capturing screen output or intercepting USB communication.

Common Security Mistakes to Avoid

Saving your seed in a notes app, email draft, cloud document, or password manager exposes it to remote attackers. If any of those services are breached—or if your device is compromised by malware—your seed is stolen too. Always keep your seed on paper or metal, offline, and away from any networked device.
Malware on your computer can silently replace a recipient address at the moment you paste it into a send form. Your Trezor’s screen is tamper-proof and always shows the actual address it will sign for. If the address on the screen does not match your intended recipient, reject the transaction immediately.
Running old firmware means missing critical security patches. Attackers are aware of published vulnerabilities in older firmware versions and actively target users who haven’t updated. Check for firmware updates in Trezor Suite each time you use your device and install them promptly.
No legitimate Trezor support agent, community moderator, or team member will ever ask for your PIN or passphrase. These secrets are yours alone. Sharing them—even with someone claiming to help you troubleshoot—gives that person unrestricted access to your device and your hidden wallet. If you are ever asked to share them, treat it as a scam.